# The Patching Model Is Broken: AI Is Widening the Gap Faster Than Defenders Can Close It
## The Threat
The numbers in Rapid7's Q2 2026 threat report are stark enough to demand attention: high and critical vulnerabilities (CVSS 7.0 and above) doubled year over year, from 4,268 in Q2 2025 to 8,539 in Q2 2026. That is not a spike. That is a structural shift — and the engine driving it is artificial intelligence.
Rapid7 frames the moment as "the compression era," and the name earns its keep. The gap between vulnerability disclosure and weaponized exploitation is compressing. Proof-of-concept code surfaces faster. Attacker tooling converts public vulnerability information into working access with less friction than ever before. What used to take a sophisticated team days now takes a capable actor hours. Traditional 30-day patch cycles were already aspirational for most organizations; against this tempo, they are fiction.
The specific mechanism making this worse is what Christiaan Beek, Rapid7's VP of cyber intelligence, calls the vibe coding feedback loop. AI coding assistants are generating new applications at scale — but they are drawing from old templates that carry old flaws. Researchers have already documented entire classes of AI-generated financial applications sharing identical vulnerability patterns. The same AI capability that finds vulnerabilities in existing software is simultaneously generating new software that inherits vulnerabilities from the past. It is a compounding problem with no natural ceiling.
## Severity and Impact
This report describes a systemic trend rather than a single discrete vulnerability, so the traditional CVE table does not apply directly. The critical metrics are below.
| Metric | Q2 2025 | Q2 2026 | Change |
|---|---|---|---|
| High/Critical disclosures (CVSS 7–10) | 4,268 | 8,539 | +100% YoY |
| New exploited vulnerabilities | ~37 | 40 | +8% YoY |
| "Holy Grail" vulns in exploited set | ~16 of 37 | 25 of 40 | +9 pts YoY |
| Holy Grail share of exploited total | ~43% | 62.5% | Significant increase |
"Holy Grail" is Rapid7's term for vulnerabilities requiring neither credentials nor user interaction — the attacker simply points and shoots. These now represent nearly two-thirds of all actively exploited vulnerabilities tracked in the quarter.
## Affected Products
There is no single vendor or product line at the center of this report — the exposure is systemic. Organizations most at risk share a common profile:
- Ukraine and NATO-aligned nations (Russian activity)
- US and allied government/defense targets (Iranian activity)
- Taiwan-adjacent technology and government (Chinese activity)
- Cryptocurrency, financial, and monetizable targets broadly (North Korean activity)
## Mitigations
Rapid7's core argument is that patching everything is no longer a viable strategy — defenders need an exposure-first mindset instead. Concretely, that means:
Reprioritize your triage model
Address the vibe coding attack surface
Shrink your exploitable perimeter
Assume nation-state targeting if relevant
## References
---
## HackWire Analysis
Here is the number that actually matters from this report: 25 of 40 exploited vulnerabilities in Q2 2026 required no authentication and no user interaction. That is 62.5 percent of everything defenders had to respond to in a single quarter — and it is trending up nine points year over year.
The mainstream framing of AI's security impact focuses on AI-assisted attacks as a future threat. The Rapid7 data suggests we are past that inflection point. AI is already doubling the rate of high/critical vulnerability discovery, and it is doing so continuously, not in waves. The disclosure pipeline is now permanently running faster than most organizations can consume it.
What makes this structurally dangerous — not just tactically difficult — is the vibe coding loop. Organizations are deploying AI coding tools to accelerate development while simultaneously using AI scanning to find vulnerabilities. The flaw is that the code generation side is drawing from training data that encodes historical vulnerability patterns. Security debt is being written directly into new applications at AI speed, then discovered at AI speed. The net is that defenders are chasing a moving target that is being continuously regenerated.
The asymmetry Beek describes — attackers need one entry point, defenders need to cover everything — is not new. But the AI amplification of vulnerability discovery against an expanded API and supply chain perimeter makes it qualitatively different. Traditional perimeter assumptions are gone; the exploitable surface now includes every third-party dependency, every AI-generated endpoint, and every vibe-coded internal tool that shipped without a security review.
Security teams that are still running monthly patch cycles need a different model now, not next quarter. Exposure management — continuous, prioritized by real-world exploitability, not CVSS score — is the replacement. The teams that internalize this shift will be measurably harder to breach than those waiting for the patching model to catch up with a problem it was never designed to handle.
— HackWire Editorial
## Related Coverage